Impossible Travel Across Multiple SaaS Apps (>500km, <2h) via CloudAppEvents
This rule identifies potential account compromise by detecting successful logins to at least two different SaaS applications monitored by Microsoft Cloud App Security (MCAS) within a 2-hour window, originating from geolocations separated by more than 500 kilometers. This behavior is indicative of credential sharing or account hijacking where an adversary accesses multiple cloud services rapidly from geographically distant locations.
Microsoft Sentinel (KQL)

